hhvm / packaging

The sources for how we have built the HHVM packages.
MIT License
64 stars 63 forks source link

Provide encrypted connection (https) to dl.hhvm.com #137

Closed J0WI closed 6 years ago

J0WI commented 8 years ago

Let's encrypt the web!

jwatzman commented 8 years ago

This is something we'll have to take up with OSUOSL at some point. FWIW we do provide a GPG key that signs the packages.

J0WI commented 8 years ago

GPG is fine to check plausibility, but https gives additional privacy, because others can't see exactly what you are downloading/searching for.

bauerj commented 8 years ago

FWIW, one of the repository mirrors, https://hhvm.bauerj.eu/ (:innocent:) supports HTTPS.

fredemmott commented 6 years ago

This is in progress, waiting for CA approval.

fredemmott commented 6 years ago

Done for https://dl2.hhvm.com

screen shot 2017-11-08 at 1 19 17 pm

When 3.23 is released, I'll change dl.hhvm.com to point at dl2.hhvm.com too (the certificate is valid for both)

If you decide to use this immediately, there's also a new GPG key for the apt repositories:

https://dl2.hhvm.com/conf/hhvm.gpg.key